Getting a cyber incident response plan right

Learn about the pitfalls that can make an incident response plan look great on paper, but fail in practice.

Published: By Paul Delahunty, Chief Information Security Officer, Stryve
shoppingmode
  • Cyber Security
  • Technology
  • Practice Support

Paul Delahunty, StryveMany organisations have an incident response plan. However, few have one that will actually work when a cyber incident unfolds at 2am on a bank holiday weekend.

From a legal perspective, incident response plans are often well written, comprehensive, and aligned with recognised frameworks. They tick the compliance boxes and satisfy governance requirements.

Yet when an organisation experiences a ransomware attack, data breach, or business email compromise, those same plans can quickly prove impractical.

How plans fail

The problem is rarely that the organisation lacked a plan. It might even have been a good one. The problem is that the plan was never designed to operate in the messy reality of a live crisis. Here are some key vulnerabilities to look out for in your plans.

Roles and responsibilities are unclear

Many plans identify an Incident Response Team but fail to define who has authority to make key decisions. During an incident, uncertainty over who can engage external advisers, approve communications, authorise expenditure, or notify regulators can waste valuable time.

An effective plan should leave no doubt about decision-making authority and should account for the possibility that key personnel are unavailable.

Contact details are out of date

It is surprisingly common to find plans containing obsolete phone numbers, departed employees, or suppliers that are no longer under contract.

When corporate systems are unavailable, relying solely on internal directories or email-based contact lists can leave teams unable to reach the people they need most.

Critical contacts should be reviewed regularly and maintained in an accessible offline format.

The plan assumes technology will still work

Many response procedures instruct staff to use collaboration platforms, shared drives, or email systems that may themselves be compromised or inaccessible.

Plans should identify alternative communication methods and establish secure out-of-band channels before an incident occurs.

Legal and regulatory obligations are considered too late

In the early stages of an incident, technical containment naturally becomes the priority. However, important legal issues (including preserving evidence, assessing notification obligations, protecting privilege, and documenting decisions) can be overlooked.

Early involvement of legal advisers can help organisations manage these obligations while supporting an effective operational response.

Guidance for key decisions are too vague

Instructions such as “notify senior management if necessary” or “consider informing regulators where appropriate” offer little practical guidance when events are unfolding rapidly.

Clear criteria, supported by decision trees or playbooks for common scenarios, can reduce hesitation and improve consistency.

Third parties are forgotten

Many incidents involve outsourced providers, cloud services, software vendors, insurers, forensic specialists, or external legal counsel. Yet these stakeholders are often missing from response planning.

Understanding contractual obligations, notification requirements, and engagement processes before an incident saves critical time when external assistance is needed.

Communications are improvised

Technical teams may be focused on containment while executives field questions from customers, employees, regulators, and the media.

Without pre-approved messaging templates and defined approval processes, inconsistent or inaccurate statements can increase legal, commercial, and reputational risk.

The plan has never been tested

Perhaps the most significant weakness is that the plan has never been tested.

Tabletop exercises frequently reveal assumptions that do not hold up in practice: unavailable decision-makers, missing contact information, conflicting priorities, or uncertainty about reporting obligations.

Testing allows organisations to identify and address these issues before they face a real incident.

A practical plan is a competitive advantage

The value of an incident response plan lies not in its length or sophistication but in its usability under pressure. A concise, regularly tested plan with clearly assigned responsibilities, reliable communication channels, and well-understood legal and operational procedures is likely to outperform a lengthy document that exists only to satisfy compliance requirements.

When incidents occur, organisations rarely fail because they lacked documentation. They fail because the documentation did not reflect how decisions would actually be made in a crisis.

Solicitors involved in post-incident investigations often observe the same lesson. The best plans are not the ones that look impressive in a policy binder – they are the ones that have been rehearsed, challenged, and refined before they are ever needed.

Paul Delahunty is Chief Information Security Officer at Stryve, a leading Irish multi-cloud and cybersecurity company and ICTTF Cyber Security Company of the Year 2022. Paul is CIO and IT Leaders Security Leader of the Year 2023 and 2024, and is the Tech Excellence Awards CIO of the Year 2024.